Serial No.: 10/642,878 

Applicant: Jagdeep Singh Sahota, et al. 

Response to Office Action 

Amendments to the Claims : 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 
Listing of the Claims: 

Claims 1-13 (Cancelled). 

Claim 14 (Currently Amended): A method comprising a plurality of steps, each being 
performed by hardware executing software, wherein the steps include : 

generating a verification value in response to a transaction involving a mobile electronic 
device, wherein the verification value is generated bv: usiag-unique transaction data for th e 

creating a base record comprising: 

digits for an application transaction counter overlaying the left most digits 
of a primary account number corresponding to an account upon which the 
transaction is being conducted, wherein the application transaction counter is 
incremented for each said transaction; and 

concatenated to the right most digits of the primary account number: 
a card security code for the primary account number; and 
an expiration date for the primary account number; 
bisecting the base record into a first field and a second field; 
encrypting the first field using a first encryption key; 
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performing an exclusive-OR (XOR) operation on the encrypted first field and the 

second field to produce a first result; 

encrypting the first result using a second encryption key to produce a second 

result; 

decrypting the second result using a decryption key to produce a third result; 

encrypting the third result using a third encryption key to produce a fourth result; 

sequentially extracting each value between 0 and 9 from the most-significant digit 
to the least-significant digit of the fourth result to produce a fifth result; 

sequentially extracting and subtracting hexadecimal A from each value between 
hexadecimal A and hexadecimal F from the most-significant digit to the least-significant 
digit of the fourth result to produce the sixth result; 

concatenating the fifth result and the sixth result to produce a seventh result; and 

selecting one or more values from the seventh result as the verification value; 

and 

sending the verification value for delivery to [[a]] die service provider with data in a 
magnetic stripe data format so that the service provider can verify the verification value. 

Claim 15 (Currently Amended): The method of claim 14 wherein the base record has a 
length equal to the number of digits of the primary account number corresponding to the 
account upon which the transaction is being conducted. 
th e uniqu e transaction data for th e transaction compris e s: 
a tim e of day for th e transaction; and 
a transaction amount for the transaction. 
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Claim 16 (Currently Amended): The method of claim 15, wherein the base record has a 
length of 128 bits, th e tim e of day for th e transaction corr e sponds to a tim e stomp for the 

Claim 17 (Currently Amended): The method of claim 14 wherein the steps further 
include a determination that a transaction amount for the transaction exceeds a predetermined 
threshold value prior to the generation of the verification value^ is also g e n e rated using at l e ast 
on e static data e l e m e nt s e l e ct e d from th e group consisting of an e xpiration dat e , a s e rvic e cod e , 
an account numb e r, and a combination th e reof. 

Claim 1 8 (Currently Amended): The method of claim 14 wherein the steps further 
comprise[[ing ]] a determination , prior to the generating of the verification value, that th e r e is an 
occurr e nc e of an e v e nt s e l e ct e d from th e group consisting of: a tran s action amount for th e 
transaction e xc ee ds a pred e termin e d thr e shold valu e ; and a geographic location of the transaction 
corresponds to a predetermined geographic location. 

Claim 19 (Previously presented):The method of claim 14 wherein: 
the verification value is generated on the mobile electronic device; 
the transaction is a payment transaction; and 
the mobile electronic device is a payment device. 
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Claim 20 (Previously presented): The method of claim 14 wherein the sending of the 

verification value for delivery to the service provider comprises the mobile electronic device 

transmitting the verification value to a point of sale terminal via wireless communications. 

Claim 21 (Currently amended): The method of claim 19 wherein the mobile electronic 
paym e nt device is selected from the group consisting of an integrated circuit card, a smartcard, a 
memory card, a cellular telephone, a personal digital assistant, and a computer. 

Claims 22-49 (Cancelled) 

Claim 50 (Currently amended): A method comprising a plurality of steps each being 




performed by hardware executing software, wherein the steps include : 

generating, at a point of sale terminal, unique transaction data for a transaction being 
processed by the point of sale terminal; 

sending, from the point of sale terminal in a wireless communication, the unique 
transaction data for the transaction; 

receiving, at a mobile electronic device, the unique transaction data for the transaction; 

creating, at the mobile electronic device, a base record comprising: 



digits for an application transaction counter overlaying the left most digits 
of a primary account number corresponding to an account upon which the 
transaction is being conducted, wherein the application transaction counter is 
incremented for each said transaction; and 

concatenated to the right most digits of the primary account number: 




a card security code for the primary account number; and 
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an expiration date for the primary account number; 
splitting, at the mobile electronic device, the base record into a first field and a second 

field; 

encrypting, at the mobile electronic device, the first field using a first encryption key; 

performing, at the mobile electronic device, an exclusive-OR (XOR) operation on the 
encrypted first field and the second field to produce a first result; 

encrypting, at the mobile electronic device, the first result using a second encryption key 
to produce a second result: 

decrypting, at the mobile electronic device, the second result using a decryption key to 
produce a third result; 

encrypting, at the mobile electronic device, the third result using a third encryption key to 
produce a fourth result: 

sequentially extracting, at the mobile electronic device, each value between 0 and 9 from 
the most-significant digit to the least-significant digit of the fourth result to produce a fifth result; 

sequentially extracting and subtracting, at the mobile electronic device, hexadecimal A 
from each value between hexadecimal A and hexadecimal F from the most-significant digit to 
the least-significant digit of the fourth result to produce the sixth result; 

concatenating, at the mobile electronic device, the fifth result and the sixth result to 
produce a seventh result; and 

selecting, at the mobile electronic device, one or more values from the seventh result as a 
verification value; 

sending, from the mobile electronic device, data in a magnetic stripe data format that 
includes the verification value; and 
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receiving, at the point of sale terminal in a wireless communication, the data in a 
magnetic stripe data format , wh e r e in: th e data is in th e magn e tic strip data format includ e s a 
v e rification value; and the verification valu e is g e n e rat e d by us e of th e uniqu e transaction data 
for th e transaction; 

and 

transmitting, from the point of sale terminal, the verification value for delivery to [[a]] the 
service provider so that the service provider can verify the verification value. 

Claim 51 (Currently amended): The method as defined in Claim 50, wherein the base 
record has a length equal to the number of digits of the primary account number corresponding to 
the account upon which the transaction is being conducted. 

th e uniqu e transaction data for th e transaction comprises: 

a tim e of day for the transaction; and 

a transaction amount for th e transaction. 

Claim 52 (Currently amended): The method as defined in Claim 51, wherein the base 
record has a length of 128 bits, th e tim e of day for th e transaction corr e sponds to a tim e stamp 



Claim 53 (Currently amended): The method as defined in Claim 50, wherein the steps 
further include a determination that a transaction amount for the transaction exceeds a 
predetermined threshold value prior to the generation of the verification value, is also g e n e rat e d 
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using at l e ast on e static data e l e m e nt s e l e ct e d from th e group consisting of an e xpiration dat e , a 
s e rvice cod e , an account numb e r, and a combination th e reof. 

Claim 54 (Currently amended): The method as defined in Claim 50, wherein the steps 
further comprise[[ing ]] a determination, prior to the sending, receiving and transmitting, th e r e is 
an occurr e nc e of an e v e nt s e l e ct e d from th e group consisting of: 

a transaction amount for th e transaction e xce e ds a pr e d e t e rmin e d thr e shold valu e ; and 
that a geographic location of the transaction corresponds to a predetermined geographic 
location. 

Claim 55 (Currently Amended): The method as defined in Claim 50, wherein: 
the transaction is a payment transaction; 

the verification value is generated by [[a]] die mobile electronic device in response to the 
transaction at the point of sale terminal; and 

the mobile electronic device is in communication with the point of sale terminal; and 
the mobile electronic device is a payment device. 

Claim 56 (Previously presented): The method as defined in Claim 55, wherein the 
payment device is selected from the group consisting of an integrated circuit card, a smartcard, a 
memory card, a cellular telephone, a personal digital assistant, and a computer. 

Claim 57 (Previously presented): The method as defined in Claim 50, wherein each said 
wireless communication is selected from a group consisting of a laser transmission, a radio 



8 



QB\8450843.1 



Serial No.: 10/642,878 

Applicant: Jagdeep Singh Sahota, et al. 

Response to Office Action 

frequency transmission, an infrared transmission, a Bluetooth transmission, and a wireless local 
area network transmission. 

Claim 58 (Currently Amended): An apparatus for processing a transaction between a 
consumer and a merchant, the apparatus point of sale terminal comprising: 

means for generating unique transaction data for the transaction; 

means for wirelessly sending the unique transaction data for the transaction for delivery 
to a mobile electronic device; 

means for wirelessly receiving data in a magnetic stripe format that includes a 
verification value g e n e rat e d by th e mobil e e l e ctronic d e vic e from th e uniqu e transaction data for 
th e transaction in r e spons e to th e transaction ;. 

and 

means for transmitting the verification value for delivery to a service provider so that the 
service provider can verify the verification valu e, wherein the verification value is generated by: 
creating a base record comprising: 

digits for an application transaction counter overlaying the left most digits 
of a primary account number corresponding to an account upon which the 
transaction is being conducted, wherein the application transaction counter is 
incremented for each said transaction that is conducted; and 

concatenated to the right most digits of the primary account number: 
a card security code for the primary account number; and 
an expiration date for the primary account number; 
splitting the base record into a first field and a second field; 
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encrypting the first field using a first encryption key: 

performing an exclusive-OR (XOR) operation on the encrypted first field and the 
second field to produce a first result: 

encrypting the first result using a second encryption key to produce a second 

result: 

decrypting the second result using a decryption key to produce a third result: 
encrypting the third result using a third encryption key to produce a fourth result: 
sequentially extracting each value between 0 and 9 from the most-significant digit 

to the least-significant digit of the fourth result to produce a fifth result: 

sequentially extracting and subtracting hexadecimal A from each value between 

hexadecimal A and hexadecimal F from the most-significant digit to the least-significant 

digit of the fourth result to produce the sixth result: 

concatenating the fifth result and the sixth result to produce a seventh result: and 
selecting one or more values from the seventh result as the verification value . 

Claim 59 (Currently amended): The apparatus as defined in Claim 58, wherein the base 
record has a length equal to the number of digits of the primary account number corresponding to 
the account upon which the transaction is being conducted. 

unique transaction data for th e transaction compris e s: 

a tim e of day for the transaction; and 

a transaction amount for th e transaction. 
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Claim 60 (Currently amended): The apparatus as defined in Claim 59, wherein the base 



Claim 61 (Currently amended): The apparatus as defined in Claim 58, wherein further 
comprising means for determining that a transaction amount for the transaction exceeds a 
predetermined threshold value, wherein the generating of the means for generating, the receiving 
of the means for receiving, and the transmitting of the means for transmitting occur after the 
determining means determines that the transaction amount for the transaction exceeds the 
predetermined threshold value, th e v e rification valu e is also g e nerat e d using at least on e static 
data el e m e nt s e l e ct e d from tho group consisting of an e xpiration dat e , a s e rvic e cod e , an account 
numb e r, and a combination thereof. 

Claim 62 (Currently amended): The apparatus as defined in Claim 58, further comprising 
means for determinin g that wh e th e r an e v e nt has occurr e d, wh e r e in th e e v e nt s e l e ct e d from th e 
group consisting of: a transaction amount for th e transaction exc ee ds a pr e d e t e rmin e d thr e shold 
value; and a geographic location of the transaction corresponds to a predetermined geographic 
location; and wherein the generating of the means for generating, the receiving of the means for 
receiving, and the transmitting of the means for transmitting occur after die determining means 
determines that the geographic location of the transaction corresponds to the predetermined 
geographic location e vent has occurred. . 

Claim 63 (Previously presented): The apparatus as defined in Claim 58, wherein: 



record has a length of 128 bits, th e tim e of day for tho transacts 



r e sponds 



tim e stamp 
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the transaction is a payment transaction; and 

the mobile electronic device is a payment device. 

Claim 64 (Previously presented): The apparatus as defined in Claim 63, wherein the 
payment device is selected from the group consisting of an integrated circuit card, a smartcard, a 
memory card, a cellular telephone, a personal digital assistant, and a computer. 

Claim 65 (Previously presented): The apparatus as defined in Claim 64, wherein each 
said wireless communication is selected from a group consisting of a laser transmission, a radio 
frequency transmission, an infrared transmission, a Bluetooth transmission, and a wireless local 
area network transmission. 



12 



QB\8450843.1 



